CVE-2005-2972
EPSS 2.7%
Description
Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.
How to fix CVE-2005-2972
To remediate CVE-2005-2972, upgrade the affected package to a fixed version below.
- Debian/abiword—upgrade to 2.4.1-1 or later
Is CVE-2005-2972 being exploited?
Low — EPSS is 2.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.4.1-1